Skip to main content

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/10/2026 11:30 AM PDT

Description:

AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machines) and processes requests from the AWS Systems Manager service, enabling capabilities including Session Manager port forwarding to remote hosts. We identified CVE-2026-89049, a server-side request forgery issue in the remote-host port forwarding functionality. Due to improper validation of equivalent address representations, an authenticated user with port-forwarding permission could bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the managed instance's temporary IAM role credentials and acting with that role's permissions from outside the instance.

Impacted versions: < 3.3.4851.0 (all versions supporting remote-host port forwarding)

Resolution:

This issue has been addressed in SSM Agent version 3.3.4851.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Until the agent is upgraded, restrict use of the AWS-StartPortForwardingSessionToRemoteHost document by scoping ssm:StartSession IAM permissions and SSM document permissions so that untrusted principals cannot start remote-host port-forwarding sessions.

References:


Please email aws-security@amazon.com with any security questions or concerns.